Some checks failed
API and SemVer surface / api-surface (push) Has been cancelled
Native release artifact audit / audit (push) Has been cancelled
Native code generation / deterministic (push) Has been cancelled
Concurrency and resource soak audit / soak (push) Has been cancelled
Documentation / documentation (push) Has been cancelled
performance evidence / audit (push) Has been cancelled
First release candidate / non-fuzz-release-gate (push) Has been cancelled
Release platform and feature matrix / audit (push) Has been cancelled
Release platform and feature matrix / matrix (false, linux-stable-minimal, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (false, macos-stable-portable, x86_64-apple-darwin, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (false, windows-stable-portable, x86_64-pc-windows-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-msrv-portable, x86_64-unknown-linux-gnu, 1.96.0) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-default, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-features, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-release-surface, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Dependency and supply-chain audit / audit (push) Has been cancelled
50 lines
1.8 KiB
YAML
50 lines
1.8 KiB
YAML
name: Dependency and supply-chain audit
|
|
|
|
on:
|
|
push:
|
|
pull_request:
|
|
workflow_dispatch:
|
|
|
|
env:
|
|
CARGO_BUILD_JOBS: 1
|
|
CARGO_INCREMENTAL: 0
|
|
CARGO_PROFILE_DEV_DEBUG: 0
|
|
|
|
jobs:
|
|
audit:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: Cache immutable Cargo downloads and advisory database
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.cargo/registry
|
|
~/.cargo/git
|
|
~/.cargo/advisory-dbs
|
|
key: supply-chain-${{ runner.os }}-${{ hashFiles('Cargo.lock', 'deny.toml') }}
|
|
- uses: dtolnay/rust-toolchain@stable
|
|
- name: Fetch every immutable locked package archive
|
|
run: cargo fetch --locked
|
|
- name: Install pinned audit tools
|
|
run: |
|
|
cargo install --locked cargo-deny --version 0.20.2
|
|
cargo install --locked cargo-machete --version 0.9.2
|
|
- name: Record and validate the reviewed graph
|
|
run: |
|
|
mkdir -p artifacts
|
|
cargo tree --locked --workspace --all-features --target all --duplicates > artifacts/dependency-duplicates.txt
|
|
cargo run --locked -p metacrate-ci-matrix -- dependency-audit --evidence artifacts/dependency-audit.json
|
|
cargo run --locked -p metacrate-ci-matrix -- provenance-audit --evidence artifacts/provenance-audit.json
|
|
- name: Reject advisories, licenses, duplicates, and sources outside policy
|
|
run: cargo deny check advisories licenses bans sources --hide-inclusion-graph
|
|
- name: Reject unused direct dependencies
|
|
run: cargo machete --with-metadata
|
|
- name: Upload dependency evidence
|
|
if: always()
|
|
uses: actions/upload-artifact@v3
|
|
with:
|
|
name: supply-chain-evidence
|
|
path: artifacts/
|
|
if-no-files-found: error
|